So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?
[flagged]
The problem is if companies like Apple and Microsoft that make proprietary operating systems are forced to comply by the threat of import bans, etc. That would make their less technologically sophisticated customers vulnerable to completely unnecessary risks. The EU might not think the risks are unnecessary because they gain "sovereignty", but that only helps the EU and their member states, not 99.999% of the people who live in their territory.
Ultimately, I don't think this will be implemented. They can scream "sovereignty" as much as they want, but everyone else has an incentive to resist, and it would be even more harmful to their perception of sovereignty if both Microsoft and Apple say no and the EU faces the choice of either banning 99% of computers on the consumer market (and still be unable to force the remaining open source alternatives to meaningfully comply) or backing down to foreign organizations after a public confrontation.